Bug 2487964 (CVE-2026-47162) - CVE-2026-47162 vim: Vim: Arbitrary Code Execution via crafted directory names
Summary: CVE-2026-47162 vim: Vim: Arbitrary Code Execution via crafted directory names
Keywords:
Status: NEW
Alias: CVE-2026-47162
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2491432
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-11 19:01 UTC by OSIDB Bzimport
Modified: 2026-07-13 10:56 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:38509 0 None None None 2026-07-13 06:50:08 UTC
Red Hat Product Errata RHSA-2026:38510 0 None None None 2026-07-13 07:26:38 UTC
Red Hat Product Errata RHSA-2026:38511 0 None None None 2026-07-13 10:56:03 UTC

Description OSIDB Bzimport 2026-06-11 19:01:18 UTC
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.

Comment 2 errata-xmlrpc 2026-07-13 06:50:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:38509 https://access.redhat.com/errata/RHSA-2026:38509

Comment 3 errata-xmlrpc 2026-07-13 07:26:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:38510 https://access.redhat.com/errata/RHSA-2026:38510

Comment 4 errata-xmlrpc 2026-07-13 10:56:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:38511 https://access.redhat.com/errata/RHSA-2026:38511


Note You need to log in before you can comment on or make changes to this bug.